CVE-2023-6238: Fedoraproject Fedora
Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.
A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.
Affected products
- Fedoraproject Fedora: version 38 only
- Linux Linux Kernel: affected versions not specified
Published 2023-11-21. Last modified 2026-06-17.